CVE-2004-2318: Medium severity netwin surgeftp vulnerability
The administrative interface (surgeftpmgr.cgi) for SurgeFTP Server 1.0b through 2.2k1 allows remote attackers to cause a temporary denial of service (crash) via requests with two percent (%) signs in the CMD parameter.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2004-2318?
CVE-2004-2318 is classified as a temporary denial of service vulnerability.
How is CVE-2004-2318 exploited?
CVE-2004-2318 can be exploited by sending specially crafted requests with two percent signs in the CMD parameter to the SurgeFTP administrative interface.
Which versions of SurgeFTP are affected by CVE-2004-2318?
CVE-2004-2318 affects SurgeFTP Server versions 1.0b through 2.2k1.
How can I mitigate the impact of CVE-2004-2318?
To mitigate the impact of CVE-2004-2318, it is recommended to upgrade to a version of SurgeFTP Server that is not vulnerable.
Is there a patch available for CVE-2004-2318?
There is no specific patch mentioned for CVE-2004-2318, but upgrading to a fixed version of SurgeFTP is advised.